The recent six-month infiltration campaign at Drift has left the crypto industry reeling, but a more pressing question has emerged: what drives North Korea's persistent focus on crypto, and how does its approach differ from other state-backed hacking operations? According to security experts, the answer lies in crypto's ability to provide the regime with a vital revenue stream. North Korea's urgent need for hard currency to fund its weapons programs, due to comprehensive international sanctions, makes crypto an attractive target.

Unlike Russia and Iran, which use crypto to evade sanctions and fund proxy networks, North Korea relies on crypto theft to generate direct revenue. This distinction is crucial, as it explains why North Korean hackers carry out large-scale, traceable heists on public blockchains, rather than using crypto to quietly circumvent sanctions. The regime's lack of a functioning economy and limited exports make crypto theft an essential means of accessing liquid value globally, without requiring a willing counterparty.

This focus on crypto as a target, rather than infrastructure, sets North Korea apart from other state-backed hackers. The regime's targets include exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access.

In contrast, Russia and Iran treat crypto as a means to broader geopolitical ends, targeting elections, energy infrastructure, and government systems. North Korea's operatives have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a prime example of this approach.

The crypto industry's unique architecture makes it an attractive hunting ground, with a lack of safeguards such as compliance checks and settlement delays. This means that once a transaction is signed and confirmed, it is final, making it essential to stop attacks before they happen.

The industry's emphasis on speed and innovation over governance and controls has created an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. According to experts, this is the hardest operational security problem in crypto right now, and one that the industry has yet to solve.